SUSPICIOUS — normal_5f90a550afbd7.pdf
SUSPICIOUS — normal_5f90a550afbd7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b2255bf342eb464e381da81eab2a0823413932e861af0cdf9323eb7475b82a66 - SHA-1:
5578fb541ec0d4dedce085f2e1561388d05fb66b - MD5:
a2bdbceb06390ef4caa0ab28d5d2c038 - ssdeep:
768:ZgGzpDgpoRgsQhTz6UekHnHwJQdFIwE8X78PFv/64iOOz8d7zfDjY6EyYSzW:aGFUpqKQ2dFIv8oPFvZOz8d73jvYSzW - TLSH:
T168327DF75093EC8C7A8B6B07AEAB15AD604A938C61379360548C772DC4BC4FD2F00951 - Submitted as: normal_5f90a550afbd7.pdf
- File type: pdf · Size: 45718 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=sebia+phoresis+software+manual, https://cdn.shopify.com/s/files/1/0483/7883/9191/files/feed_us_pirates_mod_apk.pdf, https://cdn.shopify.com/s/files/1/0501/2904/3651/files/properties_of_2d_shapes_worksheet_year_1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=sebia+phoresis+software+manual
- https://cdn.shopify.com/s/files/1/0483/7883/9191/files/feed_us_pirates_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0501/2904/3651/files/properties_of_2d_shapes_worksheet_year_1.pdf
- https://cdn.shopify.com/s/files/1/0501/1380/6486/files/manual_honor_view_20.pdf
- https://cdn.shopify.com/s/files/1/0503/2253/8664/files/sewevemokifefik.pdf
- https://cdn-cms.f-static.net/uploads/4374700/normal_5f8a13f2dd2e9.pdf
- https://cdn-cms.f-static.net/uploads/4368265/normal_5f8926007a275.pdf
- https://uploads.strikinglycdn.com/files/7557e90f-50d8-4025-9269-038a12597f8b/83626033442.pdf
- https://uploads.strikinglycdn.com/files/859669d4-e336-449b-b360-5edaf2e648f6/juwewamejirix.pdf
- https://uploads.strikinglycdn.com/files/2db76ecb-5581-4b44-aa0f-cb6cd1513318/vinodepazero.pdf
- https://uploads.strikinglycdn.com/files/caa37e28-c1cd-4cef-b179-6def5464e759/53994573926.pdf
- https://uploads.strikinglycdn.com/files/3c13b31d-76ab-4032-9773-62113857f613/base_dect_livebox.pdf
- https://s3.amazonaws.com/subud/xukokususelepaxevob.pdf
- https://s3.amazonaws.com/henghuili-files/72059985138.pdf
- https://s3.amazonaws.com/fasanag/xoxinelare.pdf
- https://s3.amazonaws.com/zunaduxa/5685484777.pdf
- https://buveziketi.weebly.com/uploads/1/3/1/3/131398526/sikibulomusifag.pdf
- https://winomumamo.weebly.com/uploads/1/3/1/0/131070375/184975cb2e4f6.pdf
- https://penulikadima.weebly.com/uploads/1/3/1/4/131482887/busojajilubasit_lojab.pdf
- https://botubadixebom.weebly.com/uploads/1/3/1/4/131407995/32b82.pdf
- https://uploads.strikinglycdn.com/files/9b75e682-594c-4eb4-97aa-e1d0970995c4/43327627555.pdf
- https://uploads.strikinglycdn.com/files/457e9071-b59c-4812-ab91-b513ca9fa455/abbey_of_the_arts.pdf
- https://uploads.strikinglycdn.com/files/88424825-ee95-44a4-b92f-b587add2f455/dasakudaliniwujobujob.pdf
- https://uploads.strikinglycdn.com/files/02b52086-d8bf-4b05-82e8-dbe1b5827364/faxomodexurig.pdf
- https://uploads.strikinglycdn.com/files/b2cfbbd7-a257-4b48-b662-1d2b8d5d473b/naruto_x_fem_kyuubi_fanfiction.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- buveziketi.weebly.com
- winomumamo.weebly.com
- penulikadima.weebly.com
- botubadixebom.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report